Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting (XSS) vulnerability in Microsoft Office XP SP3 allows remote attackers to inject arbitrary web script or HTML via a document that contains a "Content-Disposition: attachment" header and is accessed through a cdo: URL, which renders the content instead of raising a File Download dialog box, aka "Vulnerability in Content-Disposition Header Vulnerability."
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Microsoft Office CDO协议跨站脚本漏洞
Vulnerability Description
Microsoft Office是非常流行的办公软件套件。 Office的cdo:URI处理器没有正确地处理包含有Content-Disposition: attachment头的请求,用户跟随了恶意的链接,CDO协议处理器没有显示文件下载对话框而是在浏览器中呈现文件请求,这可能导致跨站脚本攻击。
CVSS Information
N/A
Vulnerability Type
N/A